npm packt seine riskantesten Sicherheitsprobleme an
Installationsskripte laufen nicht mehr automatisch
Freigaben per Allowlist
Git- und Remote-Abhängigkeiten unter Vorbehalt
Was Entwickler jetzt tun sollten
Mit npm v12 schließt GitHub einen zentralen Angriffsweg: Installationsskripte aus Abhängigkeiten laufen ab Juli 2026 nur noch nach ausdrücklicher Freigabe.
npm packt seine riskantesten Sicherheitsprobleme an
Installationsskripte laufen nicht mehr automatisch
Freigaben per Allowlist
Git- und Remote-Abhängigkeiten unter Vorbehalt
Was Entwickler jetzt tun sollten

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

GitHub finally pulls the plug on automatic install script execution for npm

GitHub announces npm security changes to tackle supply-chain attacks

NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

Upcoming breaking changes for npm v12 - GitHub Changelog

GitHub pulls pin on npm's auto-run scripts

npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.

The change, expected in July, will likely block one of the more common attack vectors; developers are wondering what took GitHub…

GitHub releases npm 12 with install scripts off by default and begins phasing out 2FA bypass tokens for sensitive npm actions.

GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking…

In response to recent software supply chain attacks, NPM version 12 is blocking the automatic script execution at install.

Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available…